LT Harper Recruitment Group
Incident Response Lead (DFIR)

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Incident Response Lead (DFIR) - Hybrid - Can be based anywhere in the UK - Up to £110k
The opportunity:
Do you want to lead the response to incidents that matter nationally?
A Cyber Consultancy is looking for an Incident Response Lead to join its Cyber Response Services team, reporting directly to the head of cyber response. This is a hands-on operational leadership role with a clear route into service line leadership. The team cover industries such as government, critical infrastructure and large enterprise, from ransomware through to advanced network intrusions. You will lead case managers and practitioners, stay technical in the forensics, and have a real say in how the practice grows.
Your benefits:
- Up to £110k salary
- Funded certifications and a structured training programme
- Exposure to nationally significant incidents across government and CNI
- Defined progression into senior leadership of a fast-growing capability
- Hybrid working from London or Manchester hubs
- Pension contribution and private healthcare
Your responsibilities as an Incident Response Lead will be to:
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
- Manage and coordinate a portfolio of cyber security incidents for clients, working closely with the head of cyber response
- Lead a team of case managers and practitioners through the full incident lifecycle: scoping, triage, containment, evidence preservation, eradication and recovery
- Carry out and quality-assure digital forensics on disk, volatile memory, network traffic and log data
- Own the commercial side of engagements, including scoping, costing, financial management and risk
- Help clients stand up or mature their own IR capability through playbooks, maturity assessments and tabletop exercises
- Drive the development of in-house cyber response tooling, lab environments and operating procedures
- Mentor junior team members and shape the team's learning and development
- Contribute to bids and proposals, and maintain a current view of the threat landscape for clients
- Take part in an on-call rotation and be ready to travel at short notice, sometimes for two to three weeks at a time
As an Incident Response Lead you will ideally have:


Get help with your application
Your very own career expert that helps elevate your application to the next level.
- Significant experience managing complex cyber security incidents end to end, including leading a rapid deployment incident response team
- Strong digital forensics competency, with advanced experience of tools such as X-Ways, EnCase, FTK, AXIOM/IEF or Cellebrite, and of preserving cloud data and encrypted evidence
- Technical depth in at least one of network and log analysis, Linux or Mac forensics, memory forensics, malware reverse engineering or mobile forensics
- A working programming skillset (Python preferred) and solid knowledge of enterprise Windows, Active Directory and Linux environments
- Excellent written and verbal communication, with the ability to guide senior non-technical stakeholders through a live incident
- Certifications such as CCIM, GCIH, CRIA, CCNIA, CCHIA, GCFA or GNFA are highly desirable, as are CISSP, CISM or CISA
- Current SC or DV clearance, or eligibility and willingness to obtain it
If you are interested in this role, please contact me at c.burn@ltharper.com
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Location